Everything Vardra does

Every access decision,under local control.

Vardra connects named coding agents to exact, time-boxed capabilities without returning raw credentials to the model. Here is the complete local policy path.

Local policy, not a hosted control plane

Agent identities, grants, approvals, leases, audit, and revocation stay on the operator’s Mac. Routine work does not depend on a remote policy service.

Raw values stay outside the model

The trusted local executor may use an approved credential, but model-facing MCP output contains state and redacted task output—not the secret or a reusable bearer capability.

Human input only when risk calls for it

Auto-allow keeps routine work moving inside a bounded lease. Ask-first pauses higher-risk requests for an explicit same-Mac approval or denial.

Agent identity

Named software identities

Connect each coding agent as its own attributable identity instead of inheriting the operator’s access.

Expiring connection credentials

Agent connections are scoped and time-bound, with no implicit owner or administrator authority.

Deny by default

A connected agent receives no secret capability until an exact grant authorizes it.

Immediate agent revocation

Invalidate an agent and every active lease tied to it before the next attempted use.

Exact grants

Secret-and-field scope

Authorize one exact secret field instead of exposing a whole vault, file, or environment.

Action scope

Separate metadata reads from reveal-through-executor actions so low-risk discovery grants no credential use.

TTL and use caps

Set grant expiry, maximum lease duration, and total uses to bound the blast radius.

Auto-allow or Ask-first

Choose the risk tier explicitly for every grant; there is no ambiguous global approval mode.

Brokered execution

Trusted local executor

Approved credentials reach a Vardra-controlled local execution boundary, not the model-facing response.

No raw-secret MCP output

Agent tools receive request state, non-authorizing IDs, and redacted results rather than plaintext values.

Same-Mac approval inbox

Ask-first requests appear in the native app and menu bar without phone push or a hosted approval service.

Fail-closed leases

Vault lock, daemon restart, expiry, denial, or revocation prevents further credential use.

Audit and control

Local access audit

Filter requests and decisions by agent and secret reference without recording the secret value.

Grant and lease revocation

Stop one capability, one active lease, or every lease for an agent immediately.

CLI and MCP workflows

Use the same local access policy from native macOS, retained command-line, and MCP-capable coding agents.

Encrypted vault foundation

Credentials remain sealed locally with optional blind sync; the broker adds controlled use on top.

Platform coverage

macOS
v0.1 app
Linux
v0.1 headless
CLI / MCP
v0.1 broker

Want the cryptographic detail?

Every claim on this page is backed by the same Rust crypto core that ships in our clients. Read the exact key derivation, encryption, and recovery model.

Broker your first agent task free.

Start free for 14 days

Agent Access CA$29/mo CAD. Cancel anytime.